Subscribe

Join our newsletter to stay up to date on the latest AI policy articles we publish!

Is the EU AI Act Equipped for a Crisis?

September 7, 2026
Summary
  • Cautionary Fables: The June suspension of Anthropic models and the summer hacking incidents show the importance of rules around frontier AI.
  • The EU approach: The EU AI Act offers both safety standards and checks and balances on government power.
  • Not so fast: It’s unclear whether the EU can act swiftly in restricting AI models believed to be dangerous.
  • So what: The European Commission should support a robust, well-resourced evaluator ecosystem in the EU and use its enforcement powers with confidence.

In late August, the European Commission confirmed that it had exercised its new powers under the EU AI Act, which it gained on 2 August. The AI Office formally sent requests for information to a number of general-purpose AI (GPAI) providers, asking questions on model security, external evaluations, and post-market monitoring.

These enforcement powers are timely. The past few months have seen AI agents autonomously hacking a private company and a steady rhythm of new AI model releases. On 1 September, Anthropic launched two new models, Claude Fable 5.1 and Claude Mythos 5.1, which reportedly exceed the capabilities of their previous iterations.

While the Commission’s requests for information from AI companies are an important step, its toolkit includes a wider range of powers that could be used in a crisis.

To understand the EU’s approach to AI governance and stress-test its preparedness for future AI risks, it is instructive to look at what happened when Anthropic released its first generation of Fable and Mythos models.

Lessons from the June suspension of Anthropic models

First, a recap: on 9 June, Anthropic launched Claude Fable 5, made available to the public, and Mythos 5, made available to partners in the Project Glasswing initiative. According to Anthropic itself, both models posed ‘significant risks’ without safeguards, such as helping malicious actors to conduct cyberattacks or develop bioweapons or aiding in model distillation.

Just three days later Anthropic had to suspend access to both models to comply with an emergency export control order, which the US government reportedly issued due to concerns about the models’ capabilities. The government lifted the restrictions on both models on 30 June. In contrast, the government never ordered the suspension of OpenAI’s GPT 5.5, a model which Anthropic claimed had a similar level of relevant capabilities to Claude Fable 5.

These events point to two conclusions for European readers.

First, the EU can be commended for its foresight in enacting the EU AI Act, which sets transparent standards for what constitutes a safe AI model and when the Commission can intervene, including pulling models from the market if needed.

Second, the Commission should prepare now to ensure it can act swiftly in the face of novel AI risks.

How would AI Act enforcement work?

Suppose a GPAI model placed on the EU market demonstrates an unacceptable risk of helping malicious actors develop biological weapons or launch cyberattacks. How could the EU respond now that it has its full toolkit of enforcement powers?

Under the rules for GPAI models with systemic risk, their providers must perform model evaluations, conduct risk assessment and mitigation, report serious incidents and ensure an adequate level of cybersecurity protection. Non-compliance with any of these obligations, but especially risk assessment and mitigation, may warrant urgent action by the Commission.

The European AI Office, with the help of the AI Act Scientific Panel, would be responsible for detecting an unmitigated systemic risk. Once such a risk has been detected, the Commission’s responses may include requesting information, conducting evaluations, or requesting mitigation measures from the provider. As a last resort, the Commission could restrict or remove a model from the market, or impose a fine on the provider.

The Act encourages the Commission to cooperate with providers, and also has procedural safeguards to limit the Commission’s exercise of its enforcement powers. Before taking any decisions, the Commission may initiate a so-called 'structured dialogue' with the provider. The Commission must also inform the GPAI model provider of any decision taken against it, the reasons for the decision, and available remedies. Finally, the Court of Justice of the EU has the power to review the Commission’s decisions.

How quickly could the Commission act?

While the rights and obligations outlined above enhance compliance and ensure the rule of law, what would happen if the risk was urgent?

The Commission’s implementing regulation on Articles 92 and 101 of the AI Act, adopted in July 2026, allows for interim measures in urgent cases due to a risk of serious damage to health, safety or other public interest grounds. This includes the option to prevent a GPAI model from being made available on the EU market.

Similarly, in the case of urgent measures, the Act and the Market Surveillance Regulation already limit some of the procedural rights of the providers, such as the right to be heard. Specifically, the Commission may take measures on health, safety or other relevant public interest grounds in such a way that makes it impossible to give the provider the opportunity to be heard ahead of time. In such cases, the provider must be given that opportunity as soon as possible after the measure is taken and that measure shall be promptly reviewed.

However, the Commission must take these interim measures with confidence if they are to be effective. This may require a willingness to act quickly, despite geopolitical or economic pressure to tread cautiously with foreign AI companies.

Enforcement needs strong AI evaluators

In addition, the Commission can only exercise these powers if it can quickly and reliably identify the relevant risks. For this reason, a robust, well-resourced evaluator ecosystem in the EU is an absolute necessity.

The July 2026 implementing regulation allows the Commission to establish a standing list of independent experts. While this is a sound first step, the Commission should seek to expand the pool of AI evaluation talent available to it by providing upskilling initiatives and training programmes, collaborating with universities and research institutions, and providing funding that may attract talent from abroad.

The EU AI Act gives Europe a transparent framework for both the rules governing AI companies, and the circumstances in which the Commission may enforce them. This fosters safety for the public as well as fairness and predictability for AI companies.

But having enforcement powers is one thing; using them effectively is another. How well the Commission responds to the next AI crisis depends on political will and whether it prepares its evaluator ecosystem now.

Authors
Eliška Andrš
Policy Researcher at Future of Life Institute
Subscribe to our newsletter
Share
This is some text inside of a div block.

Have something to share? Please reach out to us with your pitch.

If we decide to publish your piece, we will provide thorough editorial support.